Skip to content
Threat Feed

CPE

Cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*

3 briefs RSS
high threat

China-Linked Espionage Campaign Targeting Global Infrastructure via Integrity Technology Group

Integrity Technology Group, a Chinese for-profit entity, is conducting multi-year cyber espionage targeting government, healthcare, and religious institutions using automated vulnerability scanning, credential harvesting, and specialized data exfiltration tools.

Bash +12 Integrity Technology Group espionage china cyber-espionage microsoft-365 dcsync
3t 6c 2i
low advisory

Path Traversal Vulnerability in Progress Software Sitefinity Next.js Renderer SDK

An unauthenticated, remote attacker can exploit a path traversal vulnerability in the Progress Software Sitefinity Next.js Renderer SDK, enabling arbitrary file manipulation and unauthorized sensitive information disclosure.

Sitefinity Next.js Renderer SDK vulnerability web-application path-traversal
1c
medium advisory

Multiple Vulnerabilities in GitLab Lead to DoS and Security Policy Bypass

Multiple vulnerabilities in GitLab CE/EE allow attackers to cause remote denial of service and bypass security policies in versions 18.11.x before 18.11.4, 19.x before 19.0.1, and before 18.10.7; these vulnerabilities are tracked as CVE-2026-1402, CVE-2026-2601, CVE-2026-2710, CVE-2026-4868, CVE-2026-5296, CVE-2026-6713, and CVE-2026-8716.

GitLab Community Edition +1 gitlab vulnerability denial-of-service security-bypass CVE-2026-1402 CVE-2026-2601 CVE-2026-2710 CVE-2026-4868 +3
2r 2t 5c